Rule ID
SV-252514r982212_rule
Version
V1R9
CCIs
Any changes to the hardware, software, and/or firmware components of the information system and/or application can potentially have significant effects on the overall security of the system. Accordingly, software defined by the organization as critical must be signed with a certificate that is recognized and approved by the organization.
To check the status of the Security assessment policy subsystem, run the following command: /usr/sbin/spctl --status 2> /dev/null | /usr/bin/grep enabled If "assessments enabled" is not returned, this is a finding.
To enable the Security assessment policy subsystem, run the following command: /usr/bin/sudo /usr/sbin/spctl --master-enable